Toggle light / dark theme

WordPress Core “wp2shell” RCE flaws get public exploits, patch now

Public exploits have been released for the critical “wp2shell” remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately.

The wp2shell attack consists of two flaws, tracked as CVE-2026–63030 and CVE-2026–60137, that can be chained together to achieve pre-authentication remote code execution against WordPress installs running versions 6.9.x and 7.0.x.

The flaws were discovered by Adam Kues of Searchlight Cyber, which says an unauthenticated attacker can exploit them against a default WordPress installation.

Leave a Comment

Lifeboat Foundation respects your privacy! Your email address will not be published.

/* */